Legal

Privacy policy

This policy explains what personal data we collect when you use the Flash STB application or this website, why we collect it, and what you can do about it. We have tried to write it in plain language.

The short version. We collect very little. We do not know what you watch, we do not know what source you configured, and we do not sell or share your data for advertising. What we hold is essentially a licence record: a device identifier, whether it is activated, and the email address you gave us when you paid.

1. What we collect

In the application

  • Device identifier. A value identifying the app installation on your hardware. It is used to run the free demo and to attach a subscription to one device. It is not your name and does not on its own identify you as a person.
  • Platform and version information. Device type, operating system version and app version, sent when the app checks its licence, so we can diagnose faults and target updates.
  • Crash and error diagnostics. Where a crash occurs, a technical report containing the fault, the app state and device model. These do not contain your configured source or credentials.

When you buy an activation

  • Email address, so we can send a receipt and handle transfers, recovery and support.
  • Purchase record — amount, currency, date, and a reference from our payment processor.
  • Country, derived from the payment, for tax purposes.

We do not receive or store your full card number. Card details are handled entirely by our payment processor and never reach our systems.

When you contact support

Your email address, the content of your message, and whatever diagnostic information you choose to include.

On this website

Server logs containing IP address, timestamp, page requested and user agent, retained briefly for security and troubleshooting. [State here whether you use analytics, and if so which product and whether it is cookieless. If you use no analytics and set no non-essential cookies, say so — it is a genuine advantage and it simplifies your consent obligations.]

2. What we deliberately do not collect

  • Your configured source. Portal addresses, playlist URLs, provider usernames and passwords are stored in the application's local storage on your own device. They are not transmitted to us, we cannot read them, and we hold no copy.
  • What you watch. No viewing history, no channel or programme records, no watch duration. Playback runs directly between your device and your provider and does not traverse our infrastructure.
  • Contacts, photos, location, microphone or camera. The application does not request these permissions.
  • Advertising identifiers. The application contains no advertising and no third-party advertising or tracking SDK.

3. Why we process it, and on what legal basis

DataPurposeLegal basis (UK/EU GDPR)
Device identifierRun the free demo; bind a subscription to one device; prevent licence abusePerformance of a contract; legitimate interests
Email & purchase recordDeliver receipts, transfers, recovery and support; meet tax and accounting dutiesPerformance of a contract; legal obligation
Platform & version dataDiagnose faults; decide update targetsLegitimate interests
Crash diagnosticsFind and fix defectsLegitimate interests
Support correspondenceAnswer your enquiry and keep a record of itPerformance of a contract; legitimate interests
Website server logsSecurity, abuse prevention, troubleshootingLegitimate interests

4. Who we share it with

We do not sell personal data, and we do not share it for advertising or for any third party's own marketing. We use a small number of processors who act only on our instructions:

  • Payment processing — [processor name], to take payment and issue receipts.
  • Hosting and infrastructure — [provider name], to run the licence service and this website.
  • Email delivery and support ticketing — [provider names].
  • WhatsApp — if you choose to contact us using the chat button on this site, your phone number and the contents of your messages are handled by WhatsApp Ireland Limited (part of Meta) under its own terms and privacy policy, not ours. Using it is entirely optional; email reaches the same people. Please do not send payment card details or other sensitive information over WhatsApp.
  • App store operators — where you purchased in-app, Apple, Google, Amazon or Microsoft processes that payment under its own privacy policy and shares only a purchase confirmation with us.

We may also disclose data where required by law, valid legal process, or to establish or defend legal claims — including, as set out in our copyright policy, to a rights holder pursuing a breach of our acceptable use policy. What we can disclose is limited to the licence records described above; we cannot disclose viewing data because we do not have any.

5. International transfers

Our processors may handle data outside your country. Where data leaves the UK or EEA we rely on adequacy decisions or on standard contractual clauses with appropriate safeguards. [Name the countries and the mechanism you actually rely on.]

6. How long we keep it

  • Activation records — for as long as the licence is live, plus seven years, because they are also purchase records subject to tax retention rules.
  • Support correspondence — 24 months from the last message in the thread.
  • Crash diagnostics — 90 days.
  • Website server logs — 30 days.

7. Your rights

Depending on where you live you may have the right to access the data we hold about you, to correct it, to have it erased, to restrict or object to its processing, to receive it in a portable form, and to withdraw consent where processing relies on consent.

If you are in California, you additionally have the rights to know, delete, correct and opt out of "sale" or "sharing" under the CCPA/CPRA. We do not sell or share personal information as those terms are defined, and we do not offer financial incentives, so you will never be treated differently for exercising a right.

Exercise any of these by writing to legal@digitalworldai.net. We respond within 30 days. You may also complain to your data protection authority — in the UK, the Information Commissioner's Office at ico.org.uk.

Note that erasing your activation record ends the licence attached to it. We will tell you before doing so.

8. Children

Flash STB is not directed at children and is not intended for use by anyone under 13 (or under 16 where local law sets that threshold). We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.

9. Security

Data is transmitted over TLS and stored on access-controlled infrastructure. Access to activation records is limited to staff who need it for support and billing. No system is perfectly secure, but the deliberate consequence of holding so little is that there is little to lose.

10. Third-party sources you configure

When you enter a source into the application, your device connects directly to that third party. Their handling of your data — including your IP address and anything you send to authenticate — is governed by their privacy policy, not ours. We have no relationship with them and no ability to influence what they do. Read their policy before you use their service.

11. Changes

We may update this policy. Material changes will be announced in the application or by email to the address on your activation record, and the "last updated" date above will change.

12. Contact

1001646934 Ontario Inc., [Street address], [City, Postcode], [Country]
legal@digitalworldai.net
[Data protection officer or EU/UK representative, where you are required to appoint one.]